North Korea and Iran Drive 420% Surge in Blockchain Malware Dead Drops

1 hour ago 2 sources negative

Key takeaways:

  • BDD surge could heighten regulatory scrutiny on Tron, Aptos, and BNB Chain, pressuring investor sentiment.
  • Bitcoin's immutable ledger enables state actors, risking tougher AML rules and compliance burdens for exchanges.
  • AI-assisted malware may accelerate on-chain abuse, making smart contract platforms riskier for long-term investors.

Blockchain analytics firm Chainalysis reported Thursday that the number of instances in which attackers stored malware instructions or infrastructure data on public blockchains rose 420% over the past twelve months. The firm said the technique, called a blockchain dead drop (BDD), allows malicious payloads and command-and-control pointers to live inside on-chain transactions and smart contracts, making campaigns far harder to remove than those hosted on conventional servers or domains.

Chainalysis attributes roughly two of every three new dead-drop records as of the second quarter of 2026 to nation-state operators linked to North Korea and Iran. In one North Korea-tied campaign tracked by Google Threat Intelligence as UNC5342, infected devices were routed through Tron and Aptos transactions before converging on a single BNB Smart Chain transaction that held encrypted server addresses and configuration data. The report says this mirrors a 2025 operation in which North Korean hackers planted crypto-stealing code inside Ethereum-style smart contracts under the EtherHiding label.

Chainalysis also linked activity to Iran’s Ministry of Intelligence, saying operators encoded command-and-control routing data directly on the Bitcoin blockchain. The attackers allegedly sent tiny payments to a Bitcoin address with historical ties to Satoshi Nakamoto, using it as a permanent public reference point for infected machines. Since July 2025, malicious blockchain records have risen 440%, a jump that coincides with the spread of open-weight AI models capable of generating harmful code. Eric Jardine, Chainalysis cybercrimes research lead, said there is a “clear temporal association,” but the firm could not prove the actors actually used those models.

The findings add to broader concerns about state-sponsored crypto crime. CertiK has estimated that DPRK-linked actors have stolen about $6.75 billion since 2016 across 263 incidents, while separate Black Hat research found North Korean operators had infiltrated 1,640 companies in 57 countries. U.S. intelligence says stolen funds help finance Pyongyang’s nuclear and missile programs.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.